With the financial results, parliamentary evidence and recovery picture now in view, what the incident really tells us about dependencies, connected governance and business resilience.

When Marks & Spencer chairman Archie Norman appeared before Parliament’s Business and Trade Sub-Committee in July 2025, the retailer was still working through the consequences of one of the most disruptive cyber incidents in its history. 

The evidence session offered an unusually detailed view of what happens when a successful cyberattack reaches deep into the day-to-day running of a major organisation. Systems had been taken offline, online trading was disrupted and recovery was expected to continue for months.  

We now have a clearer picture of the eventual impact. In its 2025/26 results, M&S reported £131.3 million in incident-related costs and £100 million in insurance proceeds. Adjusted profit before tax fell 23.8% to £671.4 million, although the business returned to year-on-year profit growth in the second half.  

The value of the M&S experience as a case study goes beyond the size of that financial hit. One intrusion created consequences across technology, operations, suppliers, customer data and financial performance. Recovering required all of those relationships to be understood and managed under pressure. 

For information security, risk and compliance leaders, there is a great deal to learn from what happened. 

A Cyber Incident Quickly Became a Business Disruption 

M&S told Parliament that the initial entry to their system occurred on 17 April 2025 through sophisticated impersonation, with a third party also involved in the point of entry. 

Once the attack was identified, M&S deliberately shut down systems to protect the wider business. Norman explained that this contributed to the operational impact but was the right defensive action. Bringing those systems back online safely then became a lengthy rebuilding exercise. 

M&S General Counsel Nick Folland summed up one of the most practical lessons from the experience during the parliamentary hearing: organisations should be able to run their business on pen and paper for a period while systems are unavailable.  

It is an important test because digital services now underpin everything from logistics and payments to customer communications and workforce management. When those services disappear, the challenge facing the organisation moves very quickly beyond the security team. 

Resilience Starts With Understanding Your Dependencies 

The operational impact at M&S shows why dependencies matter. 

Its response to the attack required warehouse management systems to be disconnected. That resulted in online orders, Click & Collect and in-store ordering being paused, while manual processes were introduced to keep forecasting, ordering and replenishment running.  

Those workarounds kept stores trading, but the consequences travelled further. M&S said manual stock allocation contributed to additional markdown and waste, while Fashion, Home & Beauty online sales fell 42.9% during the first half as the online operation was gradually restored. 

That chain reaction is what makes dependencies such an important part of resilience. 

Leaders need to understand which services the business cannot afford to lose and the technology, information, people and suppliers that keep them running. They also need to know what happens elsewhere when one of those dependencies fails. 

A technology risk looks very different when it is connected to customer fulfilment, stock availability or revenue. A relatively small supplier can become business-critical through the systems it can access or the processes it supports. 

The M&S incident exposed those relationships in real time. Understanding them beforehand gives organisations a much stronger basis for deciding where resilience needs to be built. 

Preparedness Has to Work in the Real World 

M&S had invested in cybersecurity before the attack. Cyber risk had board and audit and risk committee attention, and the company had undertaken simulations and red-team exercises. 

Norman’s reflection afterwards was telling: the reality of the incident was far more intense than those exercises. M&S also expected systems rebuilding to continue for months after the initial attack. 

Preparedness therefore needs to test how the organisation will operate when the assumptions built into normal working practices disappear. 

Organisations should: 

  • Understand critical services and dependencies. Know which systems, information, suppliers and people the organisation relies on to keep operating. 
  • Assess risk in business terms. Connect security and technology risks with their operational, financial, regulatory and customer consequences. 
  • Maintain clear ownership and controls. Make responsibilities and escalation routes visible across the organisation. 
  • Monitor whether controls remain effective. Use evidence, incidents and changes in the business to identify emerging weaknesses. 
  • Test realistic disruption scenarios. Exercise response and recovery against extended outages, supplier failures and the loss of normal systems and communications. 
  • Feed lessons back into governance. Use incidents, exercises, audits and business change to update risks, controls and priorities. 

The NCSC’s Cyber Governance Code of Practice follows the same broad thinking, bringing risk management, strategy, people, incident planning and recovery, and assurance and oversight together as board-level governance responsibilities.  

Its latest guidance for highly disruptive attacks also recognises that recovery can stretch from immediate containment through days or weeks of rebuilding before the organisation returns to normal operations.  

Governance Connects the Wider Resilience Picture 

Norman’s evidence also points to another important part of the resilience challenge: knowing how all of these dependencies connect. 

He described an organisation with around 50,000 people working on its systems, spanning employees, contractors and outsourced teams, alongside a mixture of legacy and newer technology. A third party was involved in the point of entry to the attack, while the interconnectedness of the technology estate made complete compartmentalisation difficult. 

His recommendations focused heavily on those foundations. Norman described architecture as important to resilience and advised organisations to maintain a rigorous map of how systems interface, what they contain and who has access. He also made the point that strengthening the cybersecurity team alone could not address everything it was being asked to defend. 

The wider M&S response demonstrates why that matters. 

Personal customer information was also taken during the attack, potentially including contact details, dates of birth and online order histories. M&S therefore had privacy and regulatory responsibilities to manage alongside security containment, recovery, supplier questions and business continuity.  

And the technology environment organisations have to govern continues to expand. Before the attack, M&S had already introduced an AI-powered customer recommendation tool developed with external technology provider Preferabli and connected with its digital product catalogue.  

By March 2026, it said AI was supporting stock forecasting and ordering, marketing and colleague services, alongside the rollout of Microsoft Copilot to 11,000 employees.  

There is no evidence AI played any role in the cyberattack. Its relevance is the additional connectivity it illustrates. AI can depend on the same information, identities, systems and third-party providers already being considered through security and privacy governance. 

A single supplier relationship might therefore touch information security, personal data and AI. A system change might have implications across all three. An incident identified by one team may expose risks or require action elsewhere. 

When information security, privacy and AI governance can inform one another, those connections are easier to see. Risks, controls, evidence and corrective actions can move between the areas they affect instead of remaining within individual programmes. 

Over time, that creates a resilience loop: what an organisation learns in one part of its governance environment strengthens the others, creating a more complete picture as its technology, suppliers and risks change. 

That matters because the more connected a business becomes, the greater the risk of something important falling between areas of responsibility. Connected governance helps organisations see and manage those relationships before an incident exposes them. 

Regulation Is Reinforcing the Resilience Agenda 

The same focus on resilience, dependencies and ongoing governance is increasingly visible across regulation. 

Under NIS 2, cybersecurity risk-management measures span incident handling, business continuity, crisis management, supply chain security, asset management and processes for assessing whether security measures remain effective.  

For financial organisations within scope of DORA, ICT risk management, resilience testing and third-party dependencies are similarly treated as connected parts of digital operational resilience. The regulation explicitly requires organisations to consider the criticality of ICT dependencies and manage third-party risk as part of their wider ICT risk framework 

The UK is moving in the same direction. The Cyber Security and Resilience (Network and Information Systems) Bill, currently progressing through the House of Lords, is intended to update the UK’s existing NIS regime around the security and resilience of essential network and information systems. As of September 2026, it has completed Lords committee stage, with report stage scheduled for 26 October.  

Different organisations will face different combinations of these requirements, alongside data protection obligations and emerging AI governance responsibilities. The overlaps reinforce the value of understanding the underlying risks, controls and dependencies across them rather than approaching every requirement as an isolated compliance project. 

Resilience Is a Boardroom Issue 

The final part of the M&S story is what happened after the immediate crisis. 

Its 2025/26 results show the financial consequences clearly: £131.3 million in incident-related costs, including £109.3 million for systems response and recovery, alongside £100 million in insurance proceeds. 

M&S nevertheless returned to year-on-year profit growth in the second half. The company specifically pointed to its resilient balance sheet as allowing it to absorb the disruption while continuing investment in its wider transformation. 

That broadens the resilience conversation beyond technology recovery. 

An organisation may restore its systems and still have to absorb lost revenue, recovery costs, customer disruption, supplier issues, regulatory obligations and months of management attention. Financial capacity, communications, leadership and the ability to make decisions under pressure all influence the outcome. 

Boards therefore need visibility across the connections that can turn a technology problem into a business-wide event. 

The NCSC’s Cyber Governance Code makes that responsibility explicit, placing ownership of critical cyber governance actions with boards and directors and treating cyber resilience as part of protecting financial stability, continuity and customer trust. 

What Should Other Organisations Take From M&S? 

The M&S experience gives leadership teams a useful way to challenge their own assumptions. 

Do we know which services the business could least afford to lose, and everything they depend on? Do we understand where suppliers have access to critical systems and information? Could teams continue operating if core technology disappeared tomorrow? Have we tested that under conditions that resemble a real crisis? 

And as security, privacy and AI become more interconnected, can the people governing those areas see where their risks overlap? Does an issue identified in one programme reliably reach the others it affects? Are leadership teams seeing one coherent picture of business risk, or several partial ones? 

M&S experienced the connections between technology, operations, suppliers, customer information and financial performance under the pressure of a major incident. 

Other organisations have an opportunity to understand and govern those connections before they are tested in the same way. 

That is where business resilience starts: with a clear view of what the organisation depends on, governance that connects the risks around those dependencies, and the ability to keep operating, adapting and recovering when something goes wrong. 

Expand Your Knowledge

Blog: Beyond The Breach: Why The Response Is Now The Story

Blog: Moving From ‘Keep Them Out’ to ‘Keep the Business Running’

Podcast: Phishing for Trouble S2 E5: You’re compliant. Are you resilient?